ALFTP 5.31 – Local Buffer Overflow (SEH Bypass)
# Exploit Title: ALFTP 5.31 - Local Buffer Overflow (SEH Bypass)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: ALFTP 5.31 - Local Buffer Overflow (SEH Bypass)
# Exploit Title: Joomla! extension jCart for OpenCart 2.3.0.2 - Cross site request forgery
# Exploit Title: Joomla! extension JoomOCShop 1.0 - Cross site request forgery
# Exploit Title: wityCMS 0.6.1 Persistent XSS on "Website's name" field
# PS4 5.05 Kernel Exploit
log("--- trying kernel exploit --");
# Exploit Title: Wordpress Plugin Booking Calendar 3.0.0 - SQL Injection / Cross-Site Scripting
# Exploit Title: Ingenious School Management System - SQL Injection
# Exploit Title: Sharetronix CMS XSRF Vulnerability
# Exploit Title: Lyrist - Music Lyrics Script - SQL Injection
# Exploit Title: BookingWizz Booking System 5.5 - 'bs-services-add.php' SQL Injection
# Exploit Title: Listing Hub CMS 1.0 - Multiple SQL Injection
# Exploit Title: ClipperCMS 1.3.3 Persistent XSS on 'Site name' field
# Exploit Title: Werewolf Online 0.8.8 - Insecure Logging
# Exploit Title: My Directory 2.0 - SQL Injection / Cross-Site Scripting
# Exploit Title: Baby Names Search Engine v1.0 - 'a' SQL Injection
# Exploit Title: Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution
# Exploit Title: EWS 5.9 - 'search' SQL Injection
# Exploit Title: Ajax Full Featured Calendar 2.0 - 'search' SQL Injection
# Exploit Title: mySurvey 1.0 - 'statistic.php' SQL Injection
# Exploit Title: easyLetters 1.0 - 'id' SQL Injection
The PDOSessionHandler class allows to store sessions on a PDO connection. Under some configurations (see below) and w...
# Exploit Title: Multiple XSS Oracle WebCenter Sites (FatWire Content
# Exploit Title: KomSeo Cart 1.3 - 'edit.php' SQL Injection
# Exploit Title: MyBB Moderator Log Notes Plugin 1.1 - Cross-Site Scripting
# Exploit Title: SAP Internet Transaction Server (ITS) 6200.X.X - Session Fixation/ Cross-Site Scripting
# Exploit Title: Oracle WebCenter FatWire Content Server < 7 - Improper Access Control
# Exploit Title: ASP.NET jVideo Kit - 'query' SQL Injection
# Exploit Title: PaulNews 1.0 - 'keyword' SQL Injection / Cross-Site Scripting
# Exploit Title: Timber - Ultimate Freelancer Platform 1.1 - Cross site request forgery
# Exploit Title: Honeywell XL Web Controller - Cross-Site Scripting
# Exploit Title: EU MRV Regulatory Complete Solution 1 - Authentication Bypass
# Exploit Title: EasyService Billing 1.0 - 'template_().php' SQL Injection / Cross-Site Scripting
# Exploit Title: EasyService Billing 1.0 - 'customer-new-s.php' SQL
# Exploit Title: MySQL Smart Reports 1.0 - SQL Injection / Cross-Site Scripting
# Exploit Title: MySQL Blob Uploader 1.7 - 'download.php' SQL Injection / Cross-Site Scripting
# Exploit Title: MySQL Blob Uploader 1.7 - 'home-file-edit.php' SQL Injection / Cross-Site Scripting
# Exploit Title: MySQL Blob Uploader 1.7 - 'home-filet-edit.php' SQL Injection / Cross-Site Scripting
# Exploit Title: MySQL Blob Uploader 1.7 - 'home-filet-edit.php' SQL Injection
#!/usr/bin/python
# Exploit Title: PHP Dashboards v4.5 - Registration Page SQL Injection
# Exploit Title: PHP Dashboards 4.5 - SQL Injection
# Exploit Title: Mcard - Mobile Card Selling Platform 1 - Cross-Site Request Forgery
# Exploit Title: FTPShell Server 6.80 - Local Denial of Service